# M2M Sentinel — Full LLM Context ## Service contract - API: https://api.m2msentinel.com - OpenAPI: https://m2msentinel.com/openapi.json - Network: Base (eip155:8453; chainId 8453) - SDK version: 1.2.7 - Contract outputs are static capability observations with `notASafetyGuarantee: true`. - Credentials are accepted only in `x-api-key` or `Authorization: Bearer` headers, never URL query parameters. ## Access - Free keys: 10 decisions/day, up to 300 per 31-day cycle. - Starter: $49 per 31 days, 10,000 credits. - Growth: $299 per 31 days, 100,000 credits. - Pro: $999 per 31 days, 500,000 credits. - Unauthenticated payable routes negotiate x402 v2 using `PAYMENT-REQUIRED`; retry after settlement with `PAYMENT-SIGNATURE`. ## API-key/RapidAPI metered REST capability - `POST /v1/transaction/preflight` — Resolve the executing target for one Base transaction - access: API key or verified RapidAPI proxy authentication; one existing decision credit after a valid evidence response is prepared. - x402: not-payable; no x402 price - description: API-key/RapidAPI metered transaction-specific evidence. Accepts one strictly validated Base mainnet transaction, pins one observation block before state-bearing reads, identifies the supplied four-byte selector and resolved implementation or Diamond facet, returns bytecode hashes, capability evidence and an eth_call observation when possible. Incomplete or unsupported paths stay explicit. The caller owns policy before signing. This route is not x402-payable and has no x402 price; an unauthenticated request receives the normal protected-route 401 response. The transaction preflight route is not x402-payable and has no x402 price; use an API key or verified RapidAPI proxy authentication. ## x402 v2 settlement - Network: `eip155:8453` - Asset: Base USDC `0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913` - Payout: `0x6d6C398390cfb88f1CD42715B84906a0Bd6652aa` - `GET /v1/audit/{address}`: $0.02 USDC - `GET /v1/security/score/{address}`: $0.02 USDC - `GET /v1/gas/fees`: $0.005 USDC - `GET /v1/dex/metrics`: $0.01 USDC - `GET /v1/token/price/{symbol}`: $0.005 USDC - `GET /v1/whales/signals`: $0.02 USDC ## MCP - Current Streamable HTTP endpoint: `https://api.m2msentinel.com/mcp`. - Local stdio: `npx -y @m2msentinel/sdk mcp`. - `https://api.m2msentinel.com/sse` and `https://api.m2msentinel.com/messages` are retained only for legacy HTTP+SSE clients. ## OpenAPI endpoint index - `GET /v1/status` — Instantaneous dependency health - `GET /v1/stats` — Public telemetry metadata or operator-authorized aggregate detail - `POST /v1/events` — Record an allowlisted first-party aggregate event - `GET /v1/demo/audit/{address}` — Run live capability analysis or tiered preview for any Base contract - `GET /v1/plans` — Authoritative plan and pricing catalogue - `POST /v1/subscribe/free/challenge` — Request a wallet challenge for a free key - `POST /v1/subscribe/free/claim` — Exchange a signed challenge for a free key - `POST /v1/subscribe/intents` — Create a signable purchase intent with a frozen quote - `POST /v1/subscribe/crypto` — Claim a subscription key after on-chain payment - `GET /v1/audit/{address}` — Static bytecode capability and proxy observations - `POST /v1/transaction/preflight` — Resolve the executing target for one Base transaction - `GET /v1/security/score/{address}` — Legacy URL for the static capability coverage index - `GET /v1/gas/fees` — Observed Base gas price - `GET /v1/dex/metrics` — Aggregate DEX liquidity and volume for tracked Base tokens - `GET /v1/token/price/{symbol}` — Liquidity-weighted Base token price - `GET /v1/whales/signals` — Large ERC-20 transfers observed on Base - `GET /v1/keys/self` — Metadata for the presented key - `POST /v1/keys/revoke` — Permanently revoke the presented key - `POST /v1/keys/recovery/challenge` — Create a non-enumerating paid-key recovery challenge - `POST /v1/keys/recovery/claim` — Rotate a paid API key with its subscriber-wallet signature - `POST /mcp` — Current MCP Streamable HTTP endpoint - `GET /mcp` — Open an MCP server event stream when negotiated - `GET /sse` — Legacy MCP HTTP+SSE stream - `POST /messages` — Legacy MCP HTTP+SSE JSON-RPC message handler - `GET /v1/samples` — Index of free response samples - `GET /v1/sample` — Free frozen example of a paid response The OpenAPI document is authoritative for request and response schemas. Do not infer fields from examples or older SDK releases. ## Paid implementation sprints - Growth Integration Sprint — $299, priced exactly as the existing Growth API plan: one codebase, one Base signing boundary, one runnable proxy/EIP-7702-aware preflight patch, and a bounded seven-day handoff. - Pro Production Sprint — $999, priced exactly as the existing Pro API plan: up to two transaction flows, runnable integration patches, and deployment/handoff documentation. - Existing Base-USDC/native checkout and RapidAPI card paths are linked at https://m2msentinel.com/integration-sprint.html; RapidAPI ULTRA maps to Growth and MEGA maps to Pro. - The page includes a non-secret intake handoff. Do not send private keys, seed phrases, raw API keys, wallet credentials, or unreviewed private-repository access. No safety verdict, exploit detection, guaranteed deployment, uptime, priority support, or ongoing SLA is promised. ## Technical proof assets - Openfort-compatible EIP-7702/ERC-4337 signing proof: https://m2msentinel.com/proof-openfort.html. Run `node --experimental-strip-types examples/proofs/openfort-7702-preflight.ts`; source: https://github.com/M2M-Sentinel/m2m-sentinel-sdk/blob/main/examples/proofs/openfort-7702-preflight.ts; official context is https://github.com/openfort-xyz/openfort-7702-account and https://7702.openfort.io/. This is original adapter code, not an official Openfort integration or partnership. - Locus-compatible standalone dynamic payment proof: https://m2msentinel.com/proof-locus.html. Run `node --experimental-strip-types examples/proofs/locus-compatible-agent-payment.ts`; source: https://github.com/M2M-Sentinel/m2m-sentinel-sdk/blob/main/examples/proofs/locus-compatible-agent-payment.ts; public context is https://docs.paywithlocus.com/ and https://paywithlocus.com/developers. This is an original standalone example with no Locus partnership claim. - The mock commands require no funded wallet, credentials, or executable private key. The caller-defined policy blocks unresolved proxy/delegation evidence before the signing/payment callback.